CVE-2026-67401 lets an ordinary cPanel mail account escalate to root through a SQL injection in the EmailTrack delivery-log feature. cPanel disclosed the vulnerability class but has not published the vulnerable parameter or the query behind it.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence35
ABB's PCM600 IED manager, versions 2.14 and earlier, lets a standard local user take control of the host through a Scheduler Service running as LocalSystem. ABB's remedy is a workaround it says reduces the risk without correcting the underlying flaw.
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence66
DIVD said attackers chained two Zammad zero-days on its own internet-facing server and went from a hijacked session to root in seconds. It assessed that an AI agent was involved and says upgrading to version 7 is not a complete fix for both flaws.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+15
- Incentives35
- Confidence50
Microsoft's record September release fixed up to 997 CVEs, including two local escalations to SYSTEM that attackers used before the patch shipped. A 7.8 score understates the step that turns a phishing foothold into control of the machine, so both go ahead of the 9.8 remote flaws.
Reality
- Evidence48
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence42
Copy Fail, tracked as CVE-2026-31431, lets any unprivileged local user write a chosen four bytes into the page cache of any readable file. Because it fires every time the right syscalls run in order, timing-based mitigations do not apply.
Reality
- Evidence34
- Adoption
- Insufficient
- Hype gap+32
- Incentives42
- Confidence30
CVE-2026-86060, the privilege half of the MikroTrick chain CERT Polska analysed, lets an SSH client set its own policy mask and take RouterOS full-group admin. The September 2026 releases fix it, and a scan found 9,559 devices reachable over SSH.
Reality
- Evidence62
- Adoption52
- Hype gap−3
- Incentives22
- Confidence58
Suspected Cl0p operators chain a FlexPLM WSDL disclosure to CVE-2026-12569 for unauthenticated code execution. No encryption stage means ransomware-tuned detections stay silent.
Perspective Coverage
8 publishers
- Builder
- Builder 25%
- Operator
- Operator 57%
- Investor
- Investor 18%
Reality
- Evidence68
- Adoption55
- Hype gap−10
- Incentives60
- Confidence62
CVE-2026-81963 in the Update Stack and CVE-2026-85880 in ALPC each take a low-privilege foothold to SYSTEM, and the remediation guidance asks for verified restarts, which is a harder number to report than install counts.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence58
cPanel's September 14 advisory covers every LiteSpeed Web Server Enterprise build before 6.3.7. The fix shipped on September 11; because auto-update may lag, administrators have to force it onto servers by hand.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+20
- Incentives
- Insufficient
- Confidence60
Researcher Rasmus Moorats published a two-flaw root chain for the OnePlus 15 on September 24, 127 days after OnePlus confirmed it and with no fix shipped. Until a patch lands, owners of affected OnePlus and OPPO phones can defend only by keeping untrusted apps off them.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+5
- Incentives60
- Confidence55
A dev.to walkthrough pins the first pass of a least-privilege review on four questions the API server already answers, and it puts create pods above get secrets in the escalation order. Aggregated roles decide how far that pass gets.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+8
- Incentives18
- Confidence55
Veeam Agent for Windows has a local flaw that promotes a standard account to SYSTEM. Exploit code has been public since September 14. Arctic Wolf says there is no official workaround for systems that cannot patch yet.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+15
- Incentives65
- Confidence55
The three kernel CVEs CISA added to its exploited-bugs catalog on Friday all need local access, and the lowest-scored of them is the one STAR Labs used for privilege escalation and container escape. Red Hat has confirmed public exploit code.
Perspective Coverage
6 publishers
- Builder
- Builder 30%
- Operator
- Operator 57%
- Investor
- Investor 13%
Reality
- Evidence74
- Adoption68
- Hype gap−8
- Incentives38
- Confidence76
A researcher posting to oss-security reports that all four proof-of-concept exploits gave an unprivileged local user root code execution on the test targets, against kernel code that has been in the tree for between 10 and 21 years.
Publishers:scour.ing
Reality
- Evidence66
- Adoption35
- Hype gap−10
- Incentives28
- Confidence62
CVE-2026-76461 is one of three flaws confirmed under active attack in a single week. Revolut's customer records left by a different route, a request sent from an email address on a government agency's own domain.
Reality
- Evidence42
- Adoption62
- Hype gap+12
- Incentives58
- Confidence47
Two RouterOS flaws published to NVD on 2026-09-05 both sit in code that runs before a session has proven who it is. An upgrade closes them. Which management services answer from the internet is still an open question.
Reality
- Evidence64
- Adoption72
- Hype gap−16
- Incentives34
- Confidence66
CVE-2026-85889 let an unauthorized attacker elevate privileges over the network in the platform enterprises use to run generative AI agents. Microsoft says the fix is already live and there is nothing for customers to install.
Reality
- Evidence58
- Adoption45
- Hype gap+18
- Incentives72
- Confidence55
The bugs sit in 14 named Azure and Copilot services and Microsoft rated all 18 critical, but the fixes were already running in production when the disclosure went out, so tenants cannot install or verify anything themselves.
Reality
- Evidence45
- Adoption60
- Hype gap+20
- Incentives65
- Confidence45
CVE-2026-31431 escalates a locally authenticated user or a compromised container workload to root through the Linux kernel's algif_aead interface. ABB has fixed it in Edgenius 3.2.4.1 for the bE100 gateway.
Reality
- Evidence72
- Adoption30
- Hype gap0
- Incentives60
- Confidence66
The 7.8-rated privilege escalation in Acronis' cPanel and WHM backup plugin needs a local account on the server to work. The hosting providers and MSPs that run those servers are the only party who can install the fix.
Perspective Coverage
4 publishers
- Builder
- Builder 28%
- Operator
- Operator 61%
- Investor
- Investor 11%
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+25
- Incentives65
- Confidence65
Earlier coverage
- Attackers have been planting web shells on Magento stores since September 4
Security · September 10, 2026 · 2 publishers
- Rogue admission webhook mutates pods while SOC dashboards show normal success rates
Build · September 10, 2026 · 1 publisher
- Patched, modern Active Directory setups largely mitigate FreeIPA's cross-realm PAC impersonation flaw, FreeIPA says
Security · September 9, 2026 · 1 publisher
- cPanel patches an EmailTrack injection that carries a mail-privileged tenant to root
Security · September 9, 2026 · 1 publisher
- Two chained RouterOS flaws hand admin to an attacker who knows a username and a modulus
Build · September 8, 2026 · 1 publisher
- An unauthenticated LDAP client can write itself into FreeIPA's administrators group
Security · September 8, 2026 · 1 publisher
- PostgreSQL's logical replication skipped the library check that guarded non-superusers
Leadership · September 5, 2026 · 1 publisher
- A CRLF injection in IXON's VPN client gives unauthenticated callers root that survives reboot
Security · September 3, 2026 · 1 publisher
- One shared-hosting customer can take root on a whole cPanel server through parked domains
Security · August 28, 2026 · 1 publisher
- Certighost turns a domain user into a Domain Controller, and the patch is only step one
Security · August 17, 2026 · 1 publisher